How Does STIR/SHAKEN Authenticate Phone Calls?

TL;DR
STIR/SHAKEN authenticates caller identity by digitally signing a calling telephone number and verifying that signature through trusted certificates before or during call delivery. It targets illegal caller ID spoofing in IP SIP networks, helping providers distinguish authenticated calls from suspicious ones while allowing local policy to determine whether failed verification produces a warning or blocks the call.
Transcript
Just take a listen to this. Hello. Congratulations. You've been selected to receive a free cruise to the Bahamas, and like most cruises, all of the expenses are included. All we would like is for you to participate in a short survey. You are receiving two free boarding passes for an all-inclusive cruise to the Bahamas. Well, congratulations on bein... Read More
Key Insights
- Illegal robocalling is more than a nuisance because it enables financial scams, consumes service-provider resources, damages impersonated businesses, and weakens public confidence in voice communications. As people become reluctant to answer unfamiliar calls, legitimate personal and commercial conversations are also disrupted.
- Caller ID spoofing is the presentation of a calling identity that does not match the actual caller. It complicates enforcement because some professionals use spoofing to protect privacy, while public alerts and appointment reminders may use calling technologies that resemble the techniques employed by scammers.
- Voice filtering is harder than email filtering because telephone calls operate as a real-time service. Providers have little reliable information before delivery, telephone numbers may be spoofed, and analyzing the conversation itself would conflict with the strong privacy expectations surrounding personal calls.
- Robocallers can profit through several models, including direct scams, accessible automated calling services, and alleged revenue sharing connected to caller-name database lookups. Under the lookup model described, money can change hands even when the recipient never answers the incoming call.
- STIR is a set of protocols that implements digital signatures for the telephone numbers claimed by calling parties. Its purpose is to provide evidence that the originating provider authenticated the caller and checked whether that caller was authorized to use the presented number.
- SHAKEN is an implementation framework for STIR that gives equipment vendors and service providers common policies and guidelines. This coordination is important because inconsistent protocol implementations across a fragmented provider landscape could create interoperability problems and weaken end-to-end caller authentication.
- STIR/SHAKEN works by placing a digitally signed identity token in the SIP header of an authenticated call. The receiving domain obtains the relevant public key from a certificate repository and verifies the signature before applying its own call-handling policy.
- STIR/SHAKEN is limited to IP SIP technologies in the framework presented. Calls can cross different endpoints, carriers, intermediate networks, and legacy environments, so authenticating SIP-originated identity addresses an important part of the problem without automatically resolving every unwanted-call scenario.
Install to Summarize YouTube Videos and Get Transcripts
Explore YouTube Video Summarizer or Get YouTube Transcript Extractor
Questions & Answers
Q: What is STIR/SHAKEN and what problem does it solve?
STIR/SHAKEN is a call-authentication approach designed to address illegal caller ID spoofing and help combat robocalling in IP SIP networks. STIR supplies protocols for digitally signing the telephone number claimed by a caller, while SHAKEN supplies implementation policies and guidelines. Together, they let receiving providers verify signed caller identity information and make more informed decisions about delivering, flagging, or dropping calls.
Q: How does STIR/SHAKEN authenticate a telephone call?
The caller's user agent creates a SIP invitation containing the claimed telephone number and sends it to an authentication server. That server authenticates the caller, checks whether the caller is authorized to use the number, creates a digitally signed identity token, and places it in the SIP header. The receiving verification server retrieves public keys from a certificate repository and uses them to verify the signature.
Q: What happens when a STIR/SHAKEN signature fails verification?
A failed signature does not necessarily produce the same outcome in every network. According to the presentation, the receiving environment can still deliver the call with a warning or flag, or it can drop the call. The result depends on the policy configured by the service provider. STIR/SHAKEN therefore supplies authentication evidence, while the provider determines the final treatment of an unverified call.
Q: Why are illegal robocalls difficult for technology to block?
Illegal robocalls are difficult to isolate because automated calling and caller ID spoofing also have legitimate uses. Weather alerts, public announcements, appointment reminders, and professional privacy protections can resemble abusive activity. Providers must distinguish these calls in real time with limited advance information, and the displayed telephone number may be false. Aggressive blocking can therefore stop legitimate business or personal calls along with scams.
Q: Why can email spam be filtered more easily than robocalls?
Email can be stored on servers, analyzed, and cleaned before it reaches the recipient. Filtering systems can examine keywords, apply blacklists, and use advanced analytics. A voice call, by contrast, is a real-time service with little preceding information beyond details such as the time and a potentially spoofed number. Inspecting call content before delivery would also violate the privacy expectations people attach to telephone conversations.
Q: What is the difference between robocalling and caller ID spoofing?
Robocalling involves automated or prerecorded calling, while caller ID spoofing involves presenting an identity or telephone number that does not represent the actual caller. The practices can occur together, but they are not equivalent. A robocall does not have to use spoofed identity information, and a spoofed call does not have to be automated. Both practices also have legitimate applications, which complicates detection and blocking.
Q: How do illegal robocalls affect consumers and businesses?
Consumers can lose money and sensitive information to scams, and repeated unwanted calls can make them distrust telephone communications. That distrust causes people to ignore calls that may be important. Businesses also struggle because many customer calls go unanswered, impersonation scams can damage their names and reputations, and legitimate calls may be incorrectly marked suspicious or blocked when providers attempt to stop illegal traffic.
Q: What are the main limitations of STIR/SHAKEN?
The framework presented focuses on IP SIP technologies, while the broader telephone system includes legacy lines, different endpoints, private branch exchanges, multiple carriers, intermediate providers, and international networks. STIR/SHAKEN authenticates the claimed calling number through signatures, but it does not by itself determine whether every authenticated call is wanted or honest. Deployment consistency and call-handling policies also influence how verification results protect recipients.
Summary & Key Takeaways
-
Illegal robocalling harms consumers, businesses, and service providers. Scams can steal money and personal information, while repeated spoofed calls erode confidence in telephone communications. Legitimate calls then go unanswered, impersonated businesses suffer reputational damage, and providers must devote network capacity and infrastructure to traffic that produces costs instead of useful service.
-
Stopping unwanted calls is difficult because robocalling and caller ID spoofing both have legitimate applications. Appointment reminders, weather alerts, public announcements, and privacy protections may use similar techniques. Voice is also delivered in real time, offers little advance information for analysis, and raises privacy concerns that make inspecting call content unacceptable to consumers.
-
STIR/SHAKEN addresses spoofing by authenticating claimed telephone numbers in IP SIP calls. An originating authentication server checks the caller and authorization, signs an identity token, and inserts it into the SIP header. A terminating verification server retrieves public keys, verifies the signature, and applies local policy to deliver, flag, or drop the call.
Read in Other Languages (beta)
Share This Summary 📚
Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator
Explore More Summaries from RSAC Cybersecurity 📚






Summarize YouTube Videos and Get Video Transcripts with 1-Click
Try YouTube Summary with ChatGPT & Claude or YouTube Transcript Generator